Bot Blocker Index

Bot Blocker Index

Bot protection is expensive, and the headline numbers are effectively unverifiable — DataDome markets “99.99% detection accuracy”. This index compares each vendor’s claim against reproducible tests on surfaces they invite us to use, anonymized real-world challenge rates, and published research.

What is a bot blocker?

A bot blocker is software or a service that detects automated, non-human traffic and blocks, challenges, or rate-limits it — usually as a WAF bot-management product, a CAPTCHA or challenge widget, or device/TLS fingerprinting built into one of those.

This index tracks named bot-blocker products and compares each vendor's marketed claim against our own reproducible tests and anonymized real-world measurements.

How do bot blockers detect bots?

Detection is layered. Our technique taxonomy groups it into network identity (IP-reputation / ASN scoring), TLS / HTTP fingerprinting (JA3/JA4 handshake and HTTP/2 frame-order mismatches), browser hardening checks (headless/automation tells such as navigator.webdriver and CDP), behavioral simulation (mouse, dwell, and scroll scoring), challenge handling (the CAPTCHA layer), and client interrogation replay (active environment probes, Kasada-style).

Most vendors combine several of these layers rather than relying on just one.

Which bot blockers does this index track?

This index currently tracks 16 bot-mitigation vendors and products, across full-suite platforms, CDN-bundled bot managers, CAPTCHA/challenge providers, and fingerprinting vendors: DataDome, HUMAN Security, Cloudflare Bot Management, Cloudflare Turnstile, Cloudflare Bot Fight Mode, Akamai Bot Manager, AWS WAF Bot Control, Fastly Bot Management, Netacea, Imperva Advanced Bot Protection, Kasada, F5 / Shape Security, Arkose Labs, Google reCAPTCHA (v3 / Enterprise), hCaptcha, Fingerprint (FingerprintJS).

Each vendor page carries its marketed claim (where captured) against our own test results and any passive measurement.

How is each bot blocker tested?

Every number on this site comes from one of three sources, detailed on our methodology page: reproducible bypass attempts run only against surfaces a vendor invites testing on, or against our own trial/free-tier deployments; passive measurement of whether a single honest, default automated client is served, challenged, or hard-blocked by a live site; or bypass rates cited from existing published research.

We never bypass a security control on a non-consenting third party's production system, and we never name a vendor's paying customer.

Key facts
What our own tests show.Across every vendor we tested on our own deployments, the same pattern holds: they reliably block a default headless bot, but the fleet’s hardened tier — a patched real browser on a residential IP — passes as human. Fingerprint, Turnstile and hCaptcha all waved it through; a fresh reCAPTCHA v3 key scored bots 0.9(“human”); and Cloudflare Bot Fight Mode waved through a plain script on a residential IP with no stealth at all. The marketed 99%+ figures describe low-effort automation — not a determined scraper.
Check any site →
Real-world outcome for a default bot, by vendor (sites detected running each; latest measurement)
Served (bot let through)ChallengedBlocked
Every vendor — claim vs. reality
VendorCategoryClaimChallenged a default botClaim vs. reality
Arkose Labscaptcha——not yet scored
Cloudflare Turnstile
Cloudflare
captcha——60/100
Google reCAPTCHA (v3 / Enterprise)
Google
captcha——45/100
hCaptcha
Intuition Machines
captcha——58/100
AWS WAF Bot Control
Amazon (AWS)
cdn-bot-manager——not yet scored
Akamai Bot Manager
Akamai
cdn-bot-manager—0.0% of 40not yet scored
Cloudflare Bot Fight Mode
Cloudflare
cdn-bot-manager——72/100
Cloudflare Bot Management
Cloudflare
cdn-bot-manager—43.2% of 44not yet scored
Fastly Bot Management
Fastly (absorbed Signal Sciences)
cdn-bot-manager——not yet scored
Kasadacdn-bot-manager—100.0% of 1*not yet scored
Fingerprint (FingerprintJS)fingerprint——55/100
DataDomefull-suite99.99%87.5% of 8not yet scored
F5 / Shape Security
F5
full-suite—50.0% of 2*not yet scored
HUMAN Security
HUMAN (absorbed PerimeterX + White Ops)
full-suite—50.0% of 2*not yet scored
Imperva Advanced Bot Protection
Thales (absorbed Distil Networks)
full-suite—66.7% of 3not yet scored
Netaceafull-suite——not yet scored

“Challenged a default bot” is a passive observation: a vanilla automated client requested each site’s public homepage; we record whether it was challenged. No bypass, no login, no content stored — see methodology.

* sample too small (n<3) to be reliable — shown for completeness only.

Passive data last measured 2026-09-26 (5d ago).

The marketed numbers, over time

Vendor claims are not fixed — they get tightened, softened, and sometimes removed. We read monthly Wayback snapshots of each vendor’s own marketing pages and publish a number only where an archived snapshot carries it and the sentence around it was reviewed and judged to be the vendor describing its own product — not a customer case study, an uptime SLA, or a traffic-composition stat. Nothing is inferred between two snapshots.

Does a residential IP help?

A bit — but less than you’d think at the homepage level. Across the same sites, a default bot from a datacenter is stopped only a few points more often than from a residential IP; a plain homepage request rarely trips the heavy challenge, so IP reputation barely moves it here. The vivid exception is challenge-on-demand products — Cloudflare Bot Fight Mode blocked our datacenter request outright (403) but served every residential client. Network identity is a real lever; how big depends on the product.

From a residential IPFrom a datacenter IP% of default bots stopped (challenged or blocked)
87.5%
71.4%